Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-49007

20
FAUCET Score

CVE-2022-49007 is a NULL pointer dereference vulnerability in the nilfs2 filesystem driver of the Linux kernel. This flaw occurs when the DAT metadata file is corrupted, leading to a crash during b-tree operations if req->pr_desc_bh is NULL. It affects various versions of the Linux kernel. The vulnerability is rated Medium (CVSS 5.5) with a local attack vector and low attack complexity. A successful exploit could lead to a denial of service (system crash) due to the NULL pointer dereference, with no impact on confidentiality or integrity. User interaction is not required. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, which is typical for a large percentage of reported vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.9.335CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.301CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.268CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.158CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.25%
Probability of exploitation in next 30 days
EPSS Percentile
16.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0025 is in the 68th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2022-49007Moderate

kernel: nilfs2: fix NULL pointer dereference in nilfs_palloc_commit_free_entry()

Oct 21, 2024

References

git.kernel.org / stable/c/165c7a3b27a3857ebf57f626b9f38b48b6792e68
Patch
git.kernel.org / stable/c/2f2c59506ae39496588ceb8b88bdbdbaed895d63
Patch
git.kernel.org / stable/c/33021419fd81efd3d729a7f19341ba4b98fe66ce
Patch
git.kernel.org / stable/c/381b84f60e549ea98cec4666c6c728b1b3318756
Patch
git.kernel.org / stable/c/9a130b72e6bd1fb07fc3cde839dc6fb53da76f07
Patch
git.kernel.org / stable/c/bc3fd3293887b4cf84a9109700faeb82de533c89
Patch
git.kernel.org / stable/c/e858917ab785afe83c14f5ac141301216ccda847
Patch
git.kernel.org / stable/c/f0a0ccda18d6fd826d7c7e7ad48a6ed61c20f8b4
Patch